⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All FinOps & System Design Interview Questions Scenario 79 of 98 in FinOps & System Design
Staff SRE / Platform Architect System Design Infrastructure as Code & Governance System Design

Q: Engineers frequently bypass Terraform during production emergencies, modifying Security Groups, opening ports, and changing IAM roles directly in the AWS/Azure console. Over time, actual cloud state diverges dangerously from Git, causing future Terraform plans to destroy resources or overwrite security patches. How do you design an automated, continuous IaC drift detection and reconciliation platform?

Architectural design for a continuous Infrastructure as Code (IaC) governance engine detecting out-of-band manual cloud modifications, alerting via Slack, and automatically reconciling state via GitOps.

#System Design #Terraform #Drift Detection #Driftctl #Atlantis #GitOps #IaC
🎙️ Candidate Opening & Architectural Context
"Configuration drift is a silent killer of cloud stability and security compliance. We designed an automated continuous drift detection and remediation platform using Driftctl, Atlantis/Terraform Cloud, and automated GitHub PR reconciliation."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Deploy Continuous Drift Scanning Daemons (Driftctl / Terraform Plan)

Scan cloud resources continuously against Terraform state files:

  • Automated Scanner: Deployed a Kubernetes CronJob running Driftctl / terraform plan -detailed-exitcode every 4 hours across 60 cloud accounts.
  • Resource Coverage: Scans security groups, IAM roles, route tables, S3 bucket policies, and RDS parameters against remote state stored in S3/DynamoDB.
Pro Tip: Scanning out-of-band continuously uncovers unauthorized manual edits long before a developer executes a manual terraform apply.
2️⃣

Classify Drift Severity & Filter Benign Ephemeral Changes

Distinguish between dangerous security regressions and harmless cloud tags:

  • Severity Tiers: Classified drift into Critical (security group opened to 0.0.0.0/0, IAM privilege escalation) and Low (auto-scaling tag changes, modified timestamps).
  • Ignore Rules: Configured driftfilter rules ignoring cloud provider auto-generated metadata (e.g. AWS default KMS aliases).
Pro Tip: Filtering out benign ephemeral cloud tags prevents alert fatigue and ensures SREs focus on genuine security drifts.
3️⃣

Correlate Drift with CloudTrail to Identify Who Made the Change

Provide immediate accountability by attaching user attribution to alerts:

  • CloudTrail Correlation: Scanner queries CloudTrail event logs to identify the exact human engineer or automation role that made the manual console modification.
  • Interactive Slack Card: Dispatches alert to #cloud-drift-sec: '🚨 Security Drift Detected in prod-vpc: Port 22 opened by user john.doe@company.com via AWS Console 23 mins ago. [Reconcile Git State] or [Adopt into Code]'.
Pro Tip: Attributing manual console changes to specific engineers creates an organizational culture of accountability and reduces rogue edits.
4️⃣

Automate Self-Healing Reconciliation via GitOps PR Generation

Close the loop by bringing infrastructure back to declared Git code:

  • Auto-Revert Mode: For Critical security resources (firewalls/IAM), automated pipeline runs terraform apply to immediately revert the manual change within 15 minutes.
  • Auto-PR Mode: For approved resource additions, automation automatically generates a GitHub pull request with the required HCL code to adopt the resource into git.
  • Drift Free Posture: Achieved 99.8% code-to-cloud parity across 14,000 cloud infrastructure resources.
Pro Tip: Automatic Git PR generation allows teams to preserve legitimate emergency changes without breaking the GitOps source of truth.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Continuous IaC drift governance uses automated scheduled scanners, CloudTrail user correlation, critical auto-reverts, and automated Git PR generation to eliminate configuration drift across enterprise cloud environments."
⚡ 60-Second Elevator Pitch Talking Points
  • Schedule continuous automated Driftctl and terraform plan scans across all cloud accounts.
  • Correlate detected drift with CloudTrail to identify the responsible engineer and timestamp.
  • Auto-revert unauthorized security changes (firewalls/IAM) within 15 minutes.
  • Generate automated GitHub PRs to adopt legitimate out-of-band changes into code.
Advertisement
Want more FinOps & System Design scenarios?
Explore our complete collection of scenario-based FinOps & System Design interview runbooks.
Browse All FinOps & System Design Questions →